Region-first endpoint review · fact-checked July 22, 2026
Kaspersky Business Security Review 2026
Kaspersky Endpoint Security 12.12 produced excellent current lab results. That doesn't make it a universal buying recommendation: US sales, updates and Kaspersky Security Network operation are prohibited, while buyers elsewhere still need legal, supply-chain and data-flow approval.
This score reflects the tested product and management stack where lawful and supportable. It isn't a recommendation for US persons, US systems or any organization whose policy prohibits the supplier.

Kaspersky Business at a glance
| Current endpoint family | Kaspersky Next EDR Foundations, EDR Optimum and XDR Optimum, with enterprise XDR options above them |
|---|---|
| Exact product tested | Kaspersky Endpoint Security for Business Select with Kaspersky Security Center 12.12; AV-Comparatives says it may also be known as Next EDR Foundations |
| AV-TEST, Mar–Apr 2026 | 6.0 protection, 6.0 performance and 6.0 usability on Windows 11 Professional |
| AV-Comparatives, Mar–Jun 2026 | 99.8% real-world protection with 1 compromise and 3 false alarms; 99.6% malware, 3.9 impact and July Approved award |
| Management | Kaspersky Security Center / cloud management, depending on edition and deployment |
| Platforms | Windows, macOS, Linux and mobile coverage exists across the family; features differ substantially by OS |
| Public price | No reliable universal price; request a regional quote with seat, workload, term, support and renewal detail |
| Critical restriction | Covered Kaspersky cybersecurity/antivirus transactions and updates are prohibited for US persons/systems under the BIS determination |
- Exact current endpoint product has excellent 2026 lab evidence
- Cloud and on-premises management choices
- Windows, Mac, Linux, server and mobile components across the stack
- Clear maturity path from EPP/root-cause analysis to EDR and XDR
- Strong false-positive results in the current business test
- You're a US person or protect US-based systems
- Supplier-origin or sanctions policy prohibits the vendor
- Customer contracts require an approved-vendor list it can't meet
- You lack staff to operate EDR/XDR alerts and response
- You can't validate telemetry, KSN and data-location terms
Regional eligibility comes before protection scores
For US buyers, the answer is settled. The US Bureau of Industry and Security Kaspersky determination says Kaspersky couldn't enter new covered agreements with US persons from July 20, 2024. From September 29, 2024, it was prohibited from providing covered antivirus signature/codebase updates or operating Kaspersky Security Network on US persons’ IT systems. Resale, integration and licensing for resale/integration are also covered.
Kaspersky’s own US small-business download page now states that downloads are unavailable for US customers. This isn't a soft “consider the risk” warning. An endpoint agent without lawful, dependable security updates isn't a defensible new control, and a procurement team shouldn't route around the restriction through another region or reseller.
BIS lists limited exceptions for purely informational or educational threat-intelligence, training, consulting and advisory services. Those exceptions don't turn the covered antivirus product into a valid US endpoint deployment. Existing US estates should follow legal counsel, regulator/customer obligations and the linked CISA enterprise removal guidance; preserve logs and staged rollback capability during migration.
Outside the US, don't infer automatic approval. Check local law and sanctions, government/sector rules, cyber-insurance conditions, customer contracts, data-residency requirements, supplier-risk policy and whether updates/support are actually deliverable to every operating country. The right answer can differ for a private retailer, a regulated bank and a government contractor in the same country.
Current Kaspersky business products: map the old names carefully
The old page described Select, Advanced and Total as if that were the complete 2026 storefront. Current global material leads with Kaspersky Next EDR Foundations, Kaspersky Next EDR Optimum and Kaspersky Next XDR Optimum, while Small Office Security remains a simpler option and larger organizations can move to broader XDR platforms.
The naming bridge matters because the independent tests still identify the agent/package in older terms. AV-Comparatives tested “Kaspersky Endpoint Security for Business (Select, with KSC) 12.12” and explicitly notes that the product may also be known as “Kaspersky Next EDR Foundations.” That supports a direct evidence link; it doesn't mean every Next tier or every OS inherited the Windows result.
| Current tier | Security level | Core use | Operational boundary |
|---|---|---|---|
| Next EDR Foundations | EPP plus basic EDR context | Endpoint prevention, controls, vulnerability visibility and root-cause analysis | Foundations has limited root-cause analysis, not the full Optimum response workflow |
| Next EDR Optimum | Essential EDR | Threat-chain visibility, IoC scans, investigation, network isolation and guided/automated response | Needs a named operator, alert triage and response playbooks |
| Next XDR Optimum | Focused XDR for smaller teams | Aggregated alerts, broader context, Active Directory visibility, cloud sandbox and response automation | More context doesn't replace a staffed SOC or incident-response retainer |
| Next XDR Expert / enterprise options | Fuller XDR | Complex multi-source detection, integration and response | Architecture, integration and analyst requirements are materially higher |
Buy the capability, not the familiar label. Ask the quote to name the exact SKU, agent version, console, supported operating systems, EDR functions, server/mobile entitlements and upgrade path. A reseller calling every tier “Endpoint Security for Business” can hide an expensive mismatch.
Independent lab results: excellent and unusually specific
AV-TEST evaluated Endpoint Security 12.12 on Windows 11 Professional during March and April 2026. It earned 6.0/6.0 for protection, performance and usability and blocked 100% of both the zero-day web/email and prevalent-malware samples in that cycle.
The detailed performance cells matter more than the badge. On AV-TEST’s standard PC, popular website launches were 16% slower versus a 29% industry average, while standard application launches were 11% slower versus 7% average. On the high-end PC those figures were 15% versus 12% and 5% versus 2%. A 6.0 performance score does not mean every workload was fastest.
The AV-Comparatives March–June 2026 business report, published July 15, used Kaspersky 12.12 on Windows 11. It measured 99.8% real-world protection: 399 of 400 cases protected, one compromise and three false alarms. The malware test reached 99.6% with zero false alarms on common business software; the uncommon/non-business band was Very Low.
Kaspersky’s June performance-impact score was 3.9, the second-lightest result in the report behind ESET’s 3.7. It received the July 2026 Approved Business Product award. Those figures apply to the documented Windows configuration—not every Next tier, Mac/Linux/mobile agent or an untouched default tenant.
Features: prevention is strong; response depends on tier
Foundations combines file, web and mail threat protection with anti-ransomware, application/web/device controls, vulnerability assessment and cloud discovery. Its useful differentiator over unmanaged antivirus is central policy plus a root-cause view that helps an administrator understand how a detection developed.
Kaspersky’s current support documentation draws a hard line: under a Foundations license, the console exposes limited Root-Cause Analysis. Full Endpoint Detection and Response is available under EDR Optimum or XDR licensing. Optimum can monitor attack progression, search indicators of compromise, isolate a Windows device, scan critical areas and quarantine/delete an object according to configured response.
| Need | Minimum sensible tier | What to verify in pilot |
|---|---|---|
| Managed malware/ransomware prevention | EDR Foundations | Policy coverage, alert routing, exclusions and root-cause detail |
| Hunt the same indicator across endpoints | EDR Optimum | IoC format/import, Windows scan scope, offline-device behavior and evidence export |
| Contain an infected workstation | EDR Optimum | Network-isolation action, allowed management channels and recovery procedure |
| Aggregate multi-source context for a small team | XDR Optimum | Actual data sources, alert correlation, AD actions, sandbox limits and response automation |
| 24/7 investigation and response | Separate MDR/SOC capability | Service owner, SLA, escalation, evidence retention and incident-response authority |
A feature checkbox isn't operational readiness. Network isolation can interrupt production; IoC scanning requires trustworthy indicators; automated remediation needs scope, approval and rollback. Document who may take each action and test it before the first real incident.
Platforms and deployment: broad family, unequal agents
Kaspersky Next can apply security profiles to Windows, macOS, Linux, Android and iOS/iPadOS devices, and the wider business downloads include dedicated Windows Server and mobile components. That breadth is real, but feature parity isn't. Advanced EDR response and IoC workflows are commonly Windows-centered; mobile management and Mac/Linux prevention have different controls.
The current Endpoint Security 12.12 Windows requirements list Windows 11/10 and a long set of server editions through Windows Server 2025. Minimum x64 workstation RAM is 2 GB and free disk space is 2 GB. Those are install minimums, not production sizing guidance, and the appearance of Windows 7 or Server 2008 R2 in a vendor list doesn't extend Microsoft support or make a legacy operating system safe.
Foundations supports cloud or on-premises management. Cloud reduces console infrastructure; on-premises Kaspersky Security Center offers more control over update timing and disconnected/segmented designs. Hybrid or air-gapped requirements should be validated against the exact license and update architecture, not assumed from a general product page.
Deployment checklist
- Inventory every workload. Separate workstations, servers, VDI, Linux, Mac, mobile, branch and disconnected segments.
- Map exact controls by OS. Record which platform gets prevention, device control, encryption, EDR telemetry, isolation and patch management.
- Choose management architecture. Validate cloud/on-prem identity, MFA, roles, audit logs, bandwidth, proxy and update repositories.
- Build pilot rings. Start with IT, then ordinary users, heavy workloads and a small server group; never deploy fleet-wide from one clean laptop test.
- Plan coexistence and removal. Don't run overlapping real-time engines without vendor guidance; rehearse uninstall and rollback before migration.
Pricing: insist on a comparable three-year quote
We didn't find a stable, universal 2026 price that could be responsibly printed here. Current global pages emphasize a 30-day trial, contact or regional partner flow. Price changes with country, seat band, workstation/server/mobile mix, tier, cloud versus on-premises management, subscription term, support and partner service.
A quote should identify SKU and version, minimum seats, every protected workload, console entitlement, EDR/XDR modules, patch/encryption options, support hours and severity targets, implementation services, renewal basis, currency/tax and exit assistance. Ask whether a server or mobile device consumes the same unit and whether Kaspersky Security Center infrastructure is included or separately operated.
Compare three-year total cost, not year-one license. Include administrator time, training, console/server operation, SIEM ingestion, storage, MDR or incident-response coverage, rollout and the cost of a future supplier-mandated migration. A lower endpoint price can be expensive if alerts have no owner.
Hands-on pilot: test the control plane, not just malware blocking
Independent tests already provide better malware samples and repeatability than an ad-hoc dangerous local test. Your pilot should target the gaps labs can't answer: your applications, network, admin workflow, data rules and incident response.
- Set the acceptance criteria. Define protection status, acceptable CPU/login/file-copy impact, alert time, response time and false-positive limit.
- Use safe checks. Exercise EICAR/AMTSO controls and benign simulations; don't download live malware onto a business network.
- Test custom software. Run signed and unsigned internal tools, PowerShell, macros, compilers, finance plugins, VPN, backups and line-of-business databases.
- Prove an alert end-to-end. Confirm console event, email/ticket notification, owner, evidence, quarantine, exception and closure.
- Exercise response. On Optimum, isolate a disposable Windows pilot, validate allowed channels and restore it using the written runbook.
- Stage updates. Measure agent/program and signature delivery through proxy/VPN/offline windows and document a rollback ring.
- Review data flow. Capture exactly what is submitted to KSN/cloud services, where it's processed, how long it's retained and which controls can reduce submission.
- Make a scored decision. Weight legal eligibility and operational fit as gates, then protection, false positives, performance, management, support and cost.
KSN, telemetry and supplier risk require written answers
Cloud reputation can improve detection speed and reduce false positives, but endpoint security can inspect sensitive paths, processes, URLs and files. Obtain the business data-processing terms and Kaspersky Security Network statement tied to the exact product/region. Review file submission, telemetry categories, processing locations, subprocessors, retention, administrator audit logs, encryption, deletion/export and private-reputation-network options.
The US government’s risk finding is a formal policy decision, not a laboratory detection result. Kaspersky disputes such allegations and publishes transparency material; a review can't adjudicate state-security claims by benchmarking malware. Procurement must treat technical efficacy and supplier jurisdiction as separate dimensions: both can be true at once—strong tested protection and an unacceptable policy risk for a given buyer.
Record the decision and renewal trigger. If law, insurer requirements, customer policy, update delivery or corporate ownership changes, the organization should know who reevaluates the control and how quickly it can migrate.
Who should choose Kaspersky Business?
- A non-US organization can lawfully procure and receive updates
- Security/procurement approves vendor jurisdiction and data flows
- The team wants cloud or on-prem central management
- Current Windows prevention evidence and low false positives matter
- An operator can own EDR/XDR alerts and response
- You're a US person, US organization or protect affected US systems
- Government, customer, insurer or internal policy excludes the supplier
- You can't guarantee signatures, code updates or support in every region
- You need turnkey 24/7 MDR but are only buying an endpoint license
- You want a public self-serve price without a partner/contract process
Alternatives: match the replacement to your operating model
| Alternative | Why compare | Watch |
|---|---|---|
| Microsoft Defender for Business / Endpoint | Microsoft 365 integration, vulnerability visibility and EDR path | Licensing and policy complexity; validate cross-platform controls |
| Bitdefender GravityZone | Current business-test participation and broad EPP/EDR portfolio | Add-on/tier sprawl and policy tuning |
| ESET PROTECT | Cross-platform management and directly tested business endpoint product | Choose the correct protection/EDR tier and staff the console |
| Avast Business Security | Simple SMB plans, Windows/Mac coverage and current lab participation | Linux/mobile and EDR/MDR requirements may need another product |
| AVG Business Security | Transparent Windows-focused pricing and simple cloud management | No direct current AVG-branded business-lab result found |
Use the business antivirus guide to score alternatives under the same pilot. Migration off Kaspersky should preserve exclusions only after review, remove the old agent cleanly, verify the replacement is reporting, and confirm every device receives current definitions before the old console is retired.
Kaspersky Business FAQ
Can US businesses use Kaspersky antivirus in 2026?
US organizations shouldn't buy or deploy covered Kaspersky antivirus/cybersecurity products. BIS prohibited new covered agreements from July 20, 2024 and covered signature/codebase updates plus KSN operation after September 29, 2024. Kaspersky’s US site says downloads are unavailable.
Is Kaspersky Endpoint Security good at malware protection?
For the exact Windows product tested, evidence is strong. AV-TEST gave Endpoint Security 12.12 6/6 for protection, performance and usability in March–April 2026. AV-Comparatives’ March–June report measured 99.8% real-world protection, 99.6% malware protection and a 3.9 performance-impact score.
What is Kaspersky Next EDR Foundations?
It's the current entry business tier combining endpoint protection, controls, vulnerability visibility and limited root-cause analysis. AV-Comparatives notes that the tested Endpoint Security for Business Select/KSC product may also be known as Next EDR Foundations.
What does EDR Optimum add?
EDR Optimum adds fuller investigation and response: threat-chain context, IoC scanning, execution prevention, quarantine/deletion, critical-area scanning and Windows network isolation. These actions still need trained ownership and tested playbooks.
Does Kaspersky Business support Mac and Linux?
The wider Kaspersky Next/business family includes Windows, macOS, Linux and mobile components, but controls aren't identical. Confirm the exact agent, OS version and EDR/response capability for every platform in your quote and pilot.
How much does Kaspersky Business cost?
There's no reliable universal price to publish. Current global buying flows are region, seat, tier and deployment dependent. Request a quote that separates workloads, console, EDR/XDR modules, support, services, renewal and three-year total cost.
Is Kaspersky Next an MDR service?
No endpoint license should be assumed to provide 24/7 managed detection and response. Next tiers add EPP, EDR or XDR tooling; verify whether a separate vendor/partner MDR service includes continuous monitoring, investigation, containment authority and SLA.
Should an existing company migrate away from Kaspersky?
US estates and organizations whose law, customer, insurer or internal policy excludes Kaspersky need a controlled migration. Elsewhere, the answer depends on eligibility, update/support continuity, data-flow approval and operating fit. Preserve logs, pilot the replacement and verify coverage before retiring the old console.
Final verdict: excellent test results can't override eligibility
Kaspersky Business earns 8.5/10 for the tested technology and management proposition where it's lawful, supported and policy-approved. Endpoint Security 12.12 has some of the clearest current evidence on this site: 6/6/6 at AV-TEST, 99.8% real-world, 99.6% malware and a 3.9 impact score at AV-Comparatives, with low false-positive concern.
For US persons and affected US systems, the buying verdict is still no. For other regions, start with legal and supplier approval, then match Foundations, EDR Optimum or XDR Optimum to actual staff and response maturity. Run the 30-day pilot, get update/data/support/renewal terms in writing and keep a migration path. Protection quality is necessary; deployability and trust are part of security too.